SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Microsoft Fixes 118 Flaws, 5 Zero Days in October 2024 Patch Tuesday

Microsoft Fixes 118 Flaws, 5 Zero Days in October 2024 Patch Tuesday

This month, Microsoft released security updates addressing 118 vulnerabilities, of which 5 were publicly disclosed zero days, and 3 were critical RCE flaws. Two of the zero days are known to have been actively exploited. The chart below offers some insight into the types of vulnerabilities found.

Oct 8, 2024By Meghana Raatni4 min read

This month, Microsoft released security updates addressing 118 vulnerabilities, of which 5 were publicly disclosed zero days, and 3 were critical RCE flaws. Two of the zero days are known to have been actively exploited. The chart below offers some insight into the types of vulnerabilities found.

You can detect and remediate such vulnerabilities instantly with a patch management tool.

Zero Day Vulnerabilities

The first two flaws mentioned were actively exploited.

CVE-2024-43573: Windows MSHTML, Platform Spoofing, CVSS 6.5 – The MSHTML platform was previously used by Internet Explorer and the Legacy version of Microsoft Edge, and its components are still present in Windows. According to Microsoft, the MSHTML platform is used by Internet Explorer mode in Microsoft Edge and other applications through web browser control.

Though unconfirmed, this issue may bypass a previous vulnerability that exploited MSHTML to spoof file extensions in alerts shown when opening files. A similar MSHTML spoofing vulnerability was disclosed last month, where attackers used Braille characters in filenames to disguise PDF files.

CVE-2024-43572: Microsoft Management Console, Remote Code Execution, CVSS 7.8 – This vulnerability enabled malicious Microsoft Saved Console (MSC) files to execute remote code on affected devices, and the fix involved blocking untrusted MSC files from being opened.

Though this flaw is known to have been actively exploited in attacks, the method used remains unclear.

CVE-2024-6197: Open Source Curl, Remote Code Execution, CVSS 7.5 – This vulnerability is in libcurl and could allow commands to be executed when Curl connects to a malicious server that presents a specially crafted TLS certificate. The fix involved updating the libcurl library, which is included with the Curl executable in Windows.

CVE-2024-20659: Windows Hyper-V, Security Feature Bypass, CVSS 7.1 – This UEFI bypass vulnerability which affects virtual machines could allow attackers to compromise both the hypervisor and the secure kernel. An attacker would need physical access to the device and must reboot it to exploit the vulnerability.

CVE-2024-43583: Winlogon, Elevation of Privilege, CVSS 7.8 – This privilege escalation vulnerability could allow attackers to gain SYSTEM-level access on Windows devices. Mitigation steps involve keeping a Microsoft first-party Input Method Editor (IME) enabled, preventing the exploitation of any vulnerabilities related to third-party IMEs.

Products Affected

  • .NET and Visual Studio
  • .NET,.NET Framework, Visual Studio
  • Azure CLI
  • Azure Monitor
  • Azure Stack
  • BranchCache
  • Code Integrity Guard
  • DeepSpeed
  • Internet Small Computer Systems Interface (iSCSI)
  • Microsoft ActiveX
  • Microsoft Configuration Manager
  • Microsoft Defender for Endpoint
  • Microsoft Graphics Component
  • Microsoft Management Console
  • Microsoft Office
  • Microsoft Office Excel
  • Microsoft Office SharePoint
  • Microsoft Office Visio
  • Microsoft Simple Certificate Enrollment Protocol
  • Microsoft WDAC OLE DB provider for SQL
  • Microsoft Windows Speech
  • OpenSSH for Windows
  • Outlook for Android
  • Power BI
  • RPC Endpoint Mapper Service
  • Remote Desktop Client
  • Role: Windows Hyper-V
  • Service Fabric
  • Sudo for Windows
  • Visual C++ Redistributable Installer
  • Visual Studio
  • Visual Studio Code
  • Windows Ancillary Function Driver for WinSock
  • Windows BitLocker
  • Windows Common Log File System Driver
  • Windows Cryptographic Services
  • Windows EFI Partition
  • Windows Hyper-V
  • Windows Kerberos
  • Windows Kernel
  • Windows Kernel-Mode Drivers
  • Windows Local Security Authority (LSA)
  • Windows MSHTML Platform
  • Windows Mobile Broadband
  • Windows NT OS Kernel
  • Windows NTFS
  • Windows Netlogon
  • Windows Network Address Translation (NAT)
  • Windows Online Certificate Status Protocol (OCSP)
  • Windows Print Spooler Components
  • Windows Remote Desktop
  • Windows Remote Desktop Licensing Service
  • Windows Remote Desktop Services
  • Windows Resilient File System (ReFS)
  • Windows Routing and Remote Access Service (RRAS)
  • Windows Scripting
  • Windows Secure Channel
  • Windows Secure Kernel Mode
  • Windows Shell
  • Windows Standards-Based Storage Management Service
  • Windows Storage
  • Windows Storage Port Driver
  • Windows Telephony Server
  • Winlogon

If you’re using any of these products, you should patch them immediately! Microsoft’s Security Update Guide details mitigations and patches for each vulnerability. You can also use tools to help you apply those patches.

Instantly Fix Risks with SanerNow Patch Management

SanerNow patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. SanerNow patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

CVE Research

CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

Jun 24, 2026

Open CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

CVE Research

CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

Jun 23, 2026

Open Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests
Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

CVE Research

Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

Jun 23, 2026

Open AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure
AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

CVE Research

AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

AryStinger represents a calculated shift in IoT threat methodology, abandoning noisy, destructive payloads in favor of silent, long-term reconnaissance infrastructure. By exploiting unpatched, end-of-life routers and NAS devices through decade-old vulnerabilities, the threat operator has assembled a distributed fleet of over 4,300 Executor nodes capable of conducting parallelized DNS enumeration, port scanning, and service fingerprinting at scale, all while masking origin behind residential IP addresses. With active development ongoing and a potential operational timeline stretching back to 2024, AryStinger underscores a growing and underappreciated risk: forgotten edge hardware is not merely a compliance gap but exploitable infrastructure.

Jun 23, 2026

Microsoft Fixes 118 Flaws, 5 Zero Days in October 2024 Patch Tuesday | SecPod